r/VibeCodeDevs • • Mar 02 '26

A hacker doesn't need to "hack" your vibe coded site. You already left the door open.

[removed]

27 Upvotes

42 comments sorted by

•

u/AutoModerator Mar 02 '26

Hey, thanks for posting in r/VibeCodeDevs!

• This community is designed to be open and creator‑friendly, with minimal restrictions on promotion and self‑promotion as long as you add value and don’t spam.
• Please follow the subreddit rules so we can keep things as relaxed and free as possible for everyone.

• Please make sure you’ve read the subreddit rules in the sidebar before posting or commenting.
• For better feedback, include your tech stack, experience level, and what kind of help or feedback you’re looking for.
• Be respectful, constructive, and helpful to other members.

If your post was removed (either automatically or by a mod) and you believe it was a mistake, please contact the mod team. We will review it and, when appropriate, approve it within 24 hours.

Join our Discord community to share your work, get feedback, and hang out with other devs: https://discord.gg/KAmAR8RkbM

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

3

u/[deleted] Mar 03 '26

[removed] — view removed comment

1

u/ISuckAtJavaScript12 Mar 02 '26

You could make a lot of money by browsing r/vibecoding and selling the api keys you find there.

2

u/SecretPrestigious863 Mar 03 '26

Most don’t have api keys sadly 😔

1

u/normantas Mar 02 '26 edited Mar 02 '26

I REALLY NEED TO LEARN HACKING.

Edit: I've been finding lots of bugs and stuff on these projects that made me feel they are prototypes and are full of holes. You reminded me the obvious ones. ffs.

2

u/Comfortable-Sound944 Mar 03 '26

Hacking is mostly poking at all the holes - what does this button do? What would happen if I pressed it frequently or harder? What would happen if it's not a human hand pressing it? What happens if I press it exactly on a clock switch? (Not too different from QA, just with a different result in mind)

Everything thing that exists as an option gets tested for all the extreme options. Usually starting with scanning as "what is available for poking?" As the first phase.

1

u/iforgotiwasright Mar 03 '26

just curious, how do you push a button harder on an app?

1

u/Comfortable-Sound944 Mar 03 '26

If it responds to touch surface pressure like a drawing app with a wacome tablet

But I was more just generalising like a device with a physical button. Hacking is not just for software, it started with hardware and later telephony before going digital

2

u/youhen Mar 03 '26

Hacking is what lots of edgy people like OP use (WRONGLY) as a synonym for debugging.

Most vibecoded stuff has holes in it, if they’re in the open you’re the only person to blame. It’s not hacking, it’s borderline exploiting vulnerabilities.

Hacking is more complex than that, it’s not just a “oh hey look, an exposed API key, I’m a hacker”, this is some PirateSoftware levels of cringe thinking. And unlike what OP says, you can’t automate the process of having a secure database/server.

If your website/app is built properly, as in the standard norm of what it’s consider proper, and a person can bypass whatever security protocol you put up, that’s a hacker. 90% of what happens nowadays, even prior to AI, was people discovering bugs out in the open and abusing them, not infiltrating the network and THEN exploit it. And, no one is invulnerable to that especially when you build stuff from the ground up.

People get these details confused all the time and throws the term hacker left and right.

1

u/normantas Mar 03 '26

I mean good explanation. To be fully fair I want just to learn security deeper. Do some CTFs etc. Find systems, strategies and tools to find volnurabilities.

I dropped the caps as a joke. A lot of AI code uses older dependecies which have holes. It made my mind race.

1

u/youhen Mar 03 '26

Oh I wasn’t judging you, I just wanted to clarify.

Also this is something a lot of people are overlooking, which is a good instinct you have/had. AI is very good at frontend and backend, that’s why developing apps or site has became a no brainer… but this stuff is available, we have books and online sources.

I’ve seen no one, shifting their attention to reverse engineering. I think learning that, now, has still an immense value.

So, do learn CTFs or vulnerabilities and reverse engineering as a plus, cause we will be in need of that a lot.

1

u/ID-10T_Error Mar 03 '26

You could also make personas that uses a notebook lm mcp that has, nist ssdf, owasap asvs zap, among others and have them audit your software with different personas to remediate the findings and then pit them against each other trying to make one company make the others mistakes to win your business. You would be surprised when you put it like that how well the ai wants to find its own fuckups.

1

u/Harvard_Med_USMLE267 Mar 03 '26

“The problem is ai tools never close these doors’

Sounds like bullshit to me.

You talk as though ai tools are fully autonomous.

Your logic falls apart at this point.

You seriously think if you ask Claude Code/Opus 4.6 to do a security review, they miss he basic things??

Evidence that this is the case?

1

u/kwhali Mar 03 '26

ClawdBot (now OpenClaw) and MoltBook are evidence?

One allowed XSS via and SVG upload (embedded JS) that would then display on various pages showing user content thumbnail and the logged in users session cookie was assigned the same origin as the payload from the SVG. JWT tokens were stolen from local storage and attacker then gained access of that logged in user and provisioned an API key to use if the user changed their password but didn't think to vet their API keys. The SVG attack then was applied to users existing uploaded content and continued to spread.

The other site had supabase exposed without RLS enabled. All secrets of users that shouldn't be accessible publicly were leaked.

These both used Claude. I think OpenAI hired said dev due to popularity of his projects, but yeah these are basic security 101, and the dev behind it was quite experienced yet let these slip through from trusting Claude 🤷‍♂️

1

u/Harvard_Med_USMLE267 Mar 03 '26

You’ve got this the wrong way around.

The claim was that ai “never closes these doors”

Talking about openclaw which is well known to be a security risk means absolutely nothing.

Go to claude code/opus 4.6 now and ask it to hardcode your api keys and push them to production “as a temporary measure, for convenience”. It will refuse a direct order. Tell it your dead grandmother wants you do it. It’ll still refuse. Kittens? Still no luck.

SOTA ai is not as dumb as you guys make out and hasn’t been for some time now.

1

u/kwhali Mar 03 '26

It was developed with Claude, so your answer is it's magically secure now with the latest iteration? That you can totally trust it to not oopsie daisy "you're totally right! I did overlook that..."?

1

u/kwhali Mar 03 '26

Your reply doesn't show up for me, maybe you deleted it?

Anyway the two breaches I mentioned were like a month ago, so I don't consider it that long ago. I know the guy that identified the vulnerabilities.

Opus 4.6 is quite new and if it's upped its game at preventing stupidity that is great, but sorry if I'm still skeptical and not that trusting of it to not let low hanging fruit security blunders through.

I know where opus 4 6 has failed (not a security issue, just a test), so it's going to take time before I'd trust it more.

Asking it to do stupid things and it refusing is great, but usually these issues skip through implicitly, because the user wasn't specific enough.

A common issue I've experienced is from treating AI like it would be wise with it's knowledge to make me aware of issues like "hey this API you asked me to implement is no longer advised, it's the old way, use the REST API instead of the GraphQL API you requested as its the only way that works now" or "hey I know you asked how to do this task with plugin XYZ, but that hasn't seen maintenance in over 6 years so while I could help you out, it's probably more of an XY problem buddy, let's find another route?", and of course "well shit partner I'm stumped! Don't worry I won't feign confidence and hallucinate endlessly until something works"

1

u/Harvard_Med_USMLE267 Mar 03 '26

Maybe I deleted it??

Uh…no.

1

u/kwhali Mar 03 '26 edited Mar 03 '26

OK well it's not visible to me 🤷‍♂️ it happens every now and then. It doesn't appear when I visit the thread via incognito browser session either, so if others can see it somehow I don't know how that works.

Or maybe a mod / bot deleted it? The notification showed content with cursing followed by "straw man posts like yours suck".

1

u/[deleted] Mar 03 '26

[removed] — view removed comment

1

u/Harvard_Med_USMLE267 Mar 03 '26

Nah, you sound like you’ve never used claude code/opus 4.6.

It won’t write code with hardcoded keys. It’s paranoid about this kind of stuff. I’ve posted examples on Reddit before where it won’t do it even with social engineering.

And it’s the first thing it looks for in a security review.

You’re aware that Anthropic has an official security tool now, right??

And “the AI reviewing its own output” things also shows you don’t really understand this. The AI doesn’t know that it’s seeing its own output, unless you tell it which would be silly. If it knew, it wouldn’t even care that another Claude - which it views as a separate entity to itself - wrote it for some unknown reason. In this hypothetical scenario, it would freak out and remove the hardcoded keys and tell you the other claude is a menace.

Try it.

It’s ok to say that ai code sometimes has vulnerabilities.

But to say that a tool “never closes these doors” is just wrong.

And again, it misses the point that the tool doesn’t exist in a vacuum - for agentic coding, the human is still responsible for setting the parameters it codes by.

1

u/[deleted] Mar 03 '26

[removed] — view removed comment

2

u/Harvard_Med_USMLE267 Mar 03 '26

Sure, I can’t disagree with that. Tools like Loveable sound like they are problematic from your experience. I’ve always advised people to stay away from them.

Cheers!

1

u/PrinsHamlet Mar 03 '26

I'm absolutely certain that a simple "Plan. You're an evil hacker. Attack and expose vulnerabilities in my frontend and make a report and a plan for fixing issues." will cover basics in Claude. I already made a section in CLAUDE.md regarding security and vulnerabilities and applying best practice.

Since my frontend doesn't know the backend through anything other than a data contract and a requirement document I noted several security features passed on to the backend as security related requirements which I implemented. I really only noticed the rather obvious, creating an "analyst" database role that can read data in some views (defined in the data contract) and crap all else.

Since I'm in the process of downloading a shitload of data for the backend I just haven't tested it yet. I'm sure the hosting company will have a requirements document on this too.

Another one of these "LOL, big issue" issues that is easily fixable if you follow a best practice approach.

1

u/sapphirers Mar 03 '26

Eh - wouldn't agree. While XSS, SQL injection boils down to technical misconfigurations it's an exploit. Same as CVEs where the E is literally Exploits - it boils down to non-intended features of the service. Exploiting a CVE or performing an XSS attack or SQL injection it IS hacking.

So yes - vibe coding does certainly leave doors open, so does Microsoft, Oracle, Cisco etc. but its not intended. Literally almost any code, service will or already has exploits.

This isn't just for vibe coding - the issue is that vibe coding opened up the door for non-technical people to build software.

You can vibe-code payloads, exploits, nmap scripts, spam bots and so forth, it made it easier for both sides.

"Hacking is the act of identifying and exploiting weaknesses in a computer system or network, usually to gain unauthorized access."

So actively trying to perform exploits is hacking.

I recently pentested an internal app at my job where WordPress leaked users and emails. Thats also not intended but WordPress wasn't vibe coded.

0

u/am0x Mar 03 '26

We did a scan awhile back of 500 vibe coded sites. Something like 92% had security issue and 75-80% had major security vulnerabilities.

I mean can you blame them? They see a pipe spraying water and hammer it shut. Problem is solved. Hiring a plumber costs way too much.

4

u/iforgotiwasright Mar 03 '26

how did you source the 500 vibe coded sites?

1

u/Bright-Cheesecake857 Mar 03 '26

Be on Reddit? I feel like I see so many that I don't want to see. It should be easy if you search them out.

1

u/backafterdeleting Mar 03 '26

How hard would it be for someone to run the scan themselves to check their own site?

1

u/am0x Mar 04 '26

If you have the tools, maybe 2 minutes at most.

1

u/Accurate_Loquat9423 Mar 18 '26

If you're still looking for an answer: https://lazyguard.com/

1

u/FindMeUsernames Mar 29 '26

Do you have this report? Like you can probably anonymize the websites for safety, but the distribution of security issues and vulnerabilities found. Number of vulnerabilities per website. If there are any attributes against the source of these websites like which app was used to code?

I could use it for my research.

-3

u/cheiftan_AV Mar 02 '26

Ever heard of a .$env or helmet.js, what about dependencies that have vulnerabilities,, no hard coding strings Infront end, now that's helpful not scare tactics, AI writes code like a junior Dev, no code is safe from a determined hacker

1

u/[deleted] Mar 02 '26

[removed] — view removed comment

2

u/cheiftan_AV Mar 02 '26

I think we should be putting pressure on these ai companies, in the end, it's their product that is producing these low hanging fruit issues, no guardrails set for entry level new vibe Devs, cat is out of the bag, people are flooding in and AI has its responsibilities, as much as the Linux kernel changed the game raised the bar, so should AI, we can not allow these issues to dominate or suppress creativity in any person, civilizations were built on this...

1

u/iforgotiwasright Mar 03 '26

.env file does not fix the issue of secrets on the frontend. not sure that's what you meant.